Commit Graph
9137 Commits
Author SHA1 Message Date
Lydia Vilchez 26fe612ea7 fix(azure): cap certificate bundle at 50 KiB before parsing
Legitimate PEM/PKCS#12 bundles are well under 10 KiB. A multi-MB
payload would waste memory on base64 decoding plus PKCS#12/PEM parsing
before the validator rejects it, so the size check runs before any
parsing. Prevents memory-exhaustion attacks from callers that hand
untrusted bytes to `validate_certificate_bundle`.
2026-08-31 18:22:56 +02:00
Lydia Vilchez bd5afb6981 fix(azure): address review feedback on Azure certificate authentication 2026-08-31 18:22:56 +02:00
Lydia Vilchez c593800e24 docs(changelog): describe Azure certificate auth alongside client-secret flow 2026-08-31 18:22:56 +02:00
Lydia Vilchez f1e331ad23 fix(azure): restore validate_arguments/setup_session positional layout and harden cert path
- Move certificate kwargs behind `*,` in `validate_arguments`, `setup_session`
  and `verify_client` so pre-existing positional callers keep binding
  `tenant_id`/`client_id`/`azure_credentials`/`region_config` correctly.
- Hoist the transient `RequestsTransport` in `verify_client` to a local so
  `finally` can close it even when `CertificateCredential.__init__` raises
  before the credential is bound.
- Drop the unused `client_id` parameter from `check_certificate_creds_env_vars`
  (no caller propagates it) and always require `AZURE_CLIENT_ID` on the
  pure env-var flow.
- Update `_normalize_pem_bundle` to iterate every private-key block so a
  bundle whose leaf pairs with a non-first key is normalized correctly;
  preserve the encrypted-key `TypeError` for single-key bundles.
- Add `inspect.signature(...).bind(...)` regressions for the restored
  signatures and a multi-key PEM regression.
2026-08-31 18:22:56 +02:00
Lydia Vilchez 2f91cf430b fix(azure): harden certificate verify_client and restore positional signatures
Address Hugo's four review comments on the certificate authentication
work:

1. `AzureProvider.__init__` and `AzureProvider.validate_static_credentials`
   inserted the certificate kwargs between existing positional
   parameters. A caller that previously passed `resource_groups` or
   `region_config` positionally would silently rebind their argument to
   a certificate flag. Both signatures now keep the pre-existing
   positional layout and mark only the certificate kwargs as
   keyword-only.

2. `verify_client`'s certificate path used to catch `ServiceRequestError`
   directly from `credential.get_token()`, but `azure.identity` wraps
   `_request_token` with `wrap_exceptions`, so a real connect or read
   timeout arrived here as `ClientAuthenticationError` and was reported
   to the user as an invalid certificate. Catch
   `ClientAuthenticationError` and walk `__cause__`/`__context__` via
   the new `_find_transport_cause`: a `ServiceRequestError` or
   `ServiceResponseError` cause maps to
   `AzureCredentialsUnavailableError`; anything else keeps the invalid
   certificate mapping. Pass `retry_total=0` so Azure Core cannot
   multiply the effective deadline, and close the transient credential
   in `finally`, logging and swallowing cleanup failures so `close()`
   cannot replace the primary typed exception.

3. Rewrite the certificate timeout tests to exercise the real
   `CertificateCredential` and `RequestsTransport` pipeline, stubbing
   only `requests.Session.request` with `ConnectTimeout` and
   `ReadTimeout`. Assert `session.request.call_count == 1` to prove
   `retry_total=0` is honoured, cover
   `test_connection(..., raise_on_exception=False)`, and add a
   cleanup-failure case proving `close()` cannot mask the typed error.

4. Add `inspect.signature(...).bind(...)` regressions for `__init__`,
   `test_connection` and `validate_static_credentials` using the
   pre-existing positional call shape, asserting the certificate
   kwargs are `KEYWORD_ONLY`.
2026-08-31 18:22:56 +02:00
Lydia Vilchez f2d0e714c8 fix(azure): enforce certificate token timeout at the HTTP transport
Replace the `ThreadPoolExecutor` + `future.result(timeout=...)` pattern
in `verify_client`'s certificate path with a `RequestsTransport` that
carries the connection/read deadlines. The executor approach could
not cancel a running `credential.get_token`, so timed-out or otherwise
failing calls left the underlying worker and network request alive:
under Entra ID degradation the API and Celery paths accumulated
background workers, and non-timeout exceptions bypassed executor
shutdown entirely.

Transport-layer timeouts terminate the request itself, so there is no
worker to leak and no cleanup path to miss. Translate the resulting
`ServiceRequestError` to `AzureCredentialsUnavailableError` to keep the
existing contract for `verify_client` and `test_connection`.

Update the timeout and leaf-first tests to match the new codepath.
2026-08-31 18:22:56 +02:00
Lydia Vilchez 936d2c02a3 fix(azure): restore test_connection positional signature and cover cert timeouts
Move `provider_id` back to its original positional slot in
`AzureProvider.test_connection`; the keyword-only barrier introduced by
the certificate kwargs was breaking external callers passing it
positionally.

Add the regression coverage Hugo asked for in the SDK PR review:
- `verify_client` translates `FuturesTimeoutError` to
  `AzureCredentialsUnavailableError` for both certificate_content and
  certificate_path (the background token-request path)
- `test_connection(..., raise_on_exception=False)` returns
  `Connection(error=AzureCredentialsUnavailableError)` for both
  certificate variants
- End-to-end leaf-first assertions for the remaining
  `CertificateCredential` call sites: `setup_session` azure_credentials
  certificate_path branch, `verify_client` with content and with path,
  and `validate_static_credentials` re-encoded output
2026-08-31 18:22:56 +02:00
Lydia Vilchez 6a52bf432d test(azure): cover Hugo's regression cases for certificate authentication
Reproduce the original bug where `--tenant-id` was ignored when
AZURE_TENANT_ID was unset: `check_certificate_creds_env_vars` must not
raise when the explicit tenant replaces a missing env var.

Add the missing `requests.exceptions.Timeout` coverage: verify_client
translates the transport error to AzureCredentialsUnavailableError, and
test_connection with raise_on_exception=False returns
Connection(error=AzureCredentialsUnavailableError) instead of a raw
transport exception.

Assert end-to-end that CertificateCredential receives a leaf-first
bundle on both the env-var / --certificate-path branch and the
azure_credentials (API/UI) branch. A regression that skips the
normalization at any call site would silently break auth today; the
helper-only test could not catch that.
2026-08-31 18:22:56 +02:00
Lydia Vilchez 5317c589b3 refactor(azure): handle encrypted PEM keys and tighten bundle test
`cryptography.hazmat.primitives.serialization.load_pem_private_key`
raises TypeError, not ValueError, when the caller passes password=None
against an encrypted key. Add TypeError to verify_client's except tuple
so that path becomes AzureNotValidCertificateContentError or
AzureNotValidCertificatePathError instead of leaking. Assert the leaf-
first ordering explicitly in the bundle test so a regression that returns
the input unchanged cannot silently pass.
2026-08-31 18:22:56 +02:00
Lydia VilchezandClaude Opus 4.7 6a411881d6 refactor(azure): address Hugo review comments on Azure certificate auth
Normalize the PEM bundle at every CertificateCredential call site so
azure-identity uses the leaf certificate for its thumbprint even when
the source bundle lists an intermediate first. `check_certificate_creds_env_vars`
now accepts the explicit CLI tenant_id/client_id so callers don't require
matching AZURE_* env vars when they already have the values. Catch
requests.exceptions.Timeout on the client-secret verification path so the
Entra ID timeout raises a typed AzureCredentialsUnavailableError instead
of leaking a requests exception.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-08-31 18:22:56 +02:00
Lydia Vilchez 6b4950f922 refactor(azure): address CodeRabbit follow-up review comments
- verify_client certificate branch now manages the ThreadPoolExecutor
  explicitly so shutdown(wait=False) on timeout does not extend the
  30s deadline while credential.get_token is still running.
- client-secret token endpoint uses the shared
  _TOKEN_ACQUISITION_TIMEOUT_SECONDS constant instead of hardcoded 30.
- setup_session env-var certificate branch catches TypeError (raised by
  load_pem_private_key when a PEM key is password-protected and no
  password is supplied) alongside binascii.Error, OSError and friends.
- setup_session re-raises AzureNotValidCertificateContentError and
  AzureNotValidCertificatePathError before the outer except Exception
  wraps them into AzureSetUpSessionError, so callers still see the
  certificate-specific error type.
- validate_arguments error message no longer names --certificate-content
  as a CLI flag (the option only exists on the API/UI credential shape).
- Changelog fragment drops the redundant 'Add' verb per the prowler
  changelog convention.
- Test paths that need a non-existent file use tmp_path instead of
  hardcoded /tmp/ locations that could collide on shared runners.
- validate_arguments, setup_identity and verify_client docstrings
  document the new certificate parameters and typed errors.
2026-08-31 18:22:56 +02:00
Lydia Vilchez d6354068af refactor(azure): harden Azure certificate authentication paths
Address the 15 findings from the SDK code review:

- Certificate bundle validation now walks every PEM certificate block so
  intermediate-before-leaf order (openssl / Key Vault exports) is
  accepted, covers encrypted PKCS#8/DSA/OpenSSH private-key labels, and
  catches cryptography.UnsupportedAlgorithm alongside ValueError.
- validate_arguments rejects --certificate-content/--certificate-path
  without --certificate-auth (or a full static-credentials trio) and no
  longer requires --tenant-id when --certificate-auth is used with an
  env-var flow. --certificate-auth --tenant-id X no longer mistakenly
  raises the browser-auth error.
- setup_session prefers explicit --tenant-id over AZURE_TENANT_ID on the
  env-var certificate path, gates the env-var check on the absence of a
  static-credentials dict, runs validate_certificate_bundle before
  instantiating CertificateCredential, and maps base64/OS errors to
  typed certificate errors.
- verify_client runs the certificate get_token off-thread with a 30s
  hard timeout so a stalled Entra ID endpoint cannot pin a request
  thread or Celery worker, and catches the same base64/OS errors on the
  certificate branch.
- _compute_certificate_thumbprint logs each parser failure instead of
  silently discarding them, and the setattr on CertificateCredential
  falls back to a module-level map keyed by id() so a future
  azure-identity release that adds __slots__ cannot break the feature.
2026-08-31 18:22:56 +02:00
Lydia Vilchez 4d368d7f1d refactor(azure): log certificate parsing errors and tighten cert tests
Address CodeRabbit review:
- Log caught exceptions in the certificate content and path validation
  handlers so failures are diagnosable from the log file, matching the
  established caught-exception logging idiom.
- Assert the full credentials dict in the certificate acceptance tests
  so a stray truthy client_secret or certificate_content that would
  route setup_session to the wrong branch is caught.
2026-08-31 18:22:56 +02:00
Lydia Vilchez 1871efba93 feat(azure): add certificate authentication to Azure SDK
Add certificate-based Service Principal authentication to the Azure
provider. AzureProvider accepts a certificate (base64 content or file
path) and authenticates via azure.identity.CertificateCredential,
mirroring the M365 provider flow. Includes CLI flags
(--certificate-auth, --certificate-content, --certificate-path),
key-pair validation for PEM and PKCS#12 bundles, and unit tests.
2026-08-31 18:22:56 +02:00
Pedro MartínandDavid 6422178b76 feat(sdk): AWS partition selection via PROWLER_AWS_PARTITION (#12680)
Co-authored-by: David <david.copo@gmail.com>
2026-08-31 18:13:30 +02:00
Daniel BarranqueroandJosema Camacho 587c47bfe2 feat(api): add finding labels, finding URL and tenant info to Jira issues (#12540)
Co-authored-by: Josema Camacho <josema@prowler.com>
2026-08-31 18:00:46 +02:00
Rubén De la Torre VicoandClaude Opus 5 13a31d9225 feat(mcp): raise instead of returning error objects in the Prowler Docs tools (#12534)
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-31 17:36:19 +02:00
Pablo Fernandez Guerra (PFE)andalejandrobailo 0715619435 feat(ui): import Prowler OCSF findings from the Scans page (#12554)
Co-authored-by: alejandrobailo <alejandrobailo94@gmail.com>
2026-08-31 17:14:12 +02:00
Rubén De la Torre Vico 1679094f22 feat(mcp): raise instead of returning error objects in the Prowler Hub tools (#12533) 2026-08-31 13:09:34 +02:00
Rubén De la Torre Vico f05a490cd7 feat(mcp): raise instead of returning error objects in the Prowler App tools (#12532) 2026-08-31 10:57:58 +02:00
Alejandro Bailo 89988dada5 fix(ui): refresh cached permissions after token rotation (#12640) 2026-08-31 10:49:10 +02:00
ye11oc4tandDaniel Barranquero 0326844527 fix(github): paginate repository discovery (#12460)
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
2026-08-31 10:15:29 +02:00
mintlify[bot] 73d5c6952b docs: fix typos and grammar (#12672)
Co-authored-by: mintlify[bot] <109931778+mintlify[bot]@users.noreply.github.com>
2026-08-31 09:18:08 +02:00
mintlify[bot] ad76b3026f docs: brand tone and writing style fixes (#12671)
Co-authored-by: mintlify[bot] <109931778+mintlify[bot]@users.noreply.github.com>
2026-08-31 09:15:46 +02:00
Utkarsh Batham e21946874f feat(memorydb): add memorydb_cluster_in_transit_encryption_enabled check (#12246) 2026-08-28 14:03:10 +02:00
SejalandDaniel Barranquero 2cae2058e9 feat(aws): add elasticbeanstalk_environment_no_secrets_in_configuration check (#12378)
Signed-off-by: unknown <sej1306kook@gmail.com>
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
2026-08-28 13:54:23 +02:00
Daniel BarranqueroandJosema Camacho c88f745038 feat(jira): return the created issue, sanitize labels and add bulk status lookup (#12539)
Co-authored-by: Josema Camacho <josema@prowler.com>
2026-08-28 13:47:12 +02:00
Prowler Botandprowler-bot c923c58a39 chore(release): Bump versions to v5.41.0 (#12647)
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com>
2026-08-28 13:16:00 +02:00
c3bee8c21e chore(changelog): v5.40.0 highlights (#12569)
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
Co-authored-by: pedrooot <pedromarting3@gmail.com>
2026-08-28 13:10:06 +02:00
Prowler Botandprowler-bot 4d13e8432e chore(changelog): v5.40.0 (#12642)
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com>
2026-08-28 11:51:30 +02:00
Pedro Martín 5f24bec9fe fix(compliance): correct Cyber Essentials mappings and remediation text (#12596) 2026-08-28 11:08:15 +02:00
César Arroba afefb8f333 fix(api): apply findings partition max age in months, not days (#12580) 2026-08-28 10:34:12 +02:00
Rubén De la Torre Vico 2b81fdcc04 fix(mcp): call the Mintlify search endpoint the documentation moved to (#12578) 2026-08-27 16:48:38 +02:00
Pablo Fernandez Guerra (PFE) db298c1d48 fix(ui): redirect the Slack OAuth callback relative to the browser's origin (#12577) 2026-08-27 16:13:36 +02:00
2877c3d6c0 fix(slack): handle scans that produce no findings (#12229)
Co-authored-by: Juhef <117518034+juheff@users.noreply.github.com>
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
2026-08-27 14:03:33 +02:00
ee64c17108 fix(kubernetes): return empty list when resource gather fails (#12225)
Co-authored-by: Juhef <117518034+juheff@users.noreply.github.com>
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
2026-08-27 13:55:46 +02:00
Pablo Fernandez Guerra (PFE)andalejandrobailo a610314eba fix(ui): complete Slack OAuth callback server-side to avoid router race (#12572)
Co-authored-by: alejandrobailo <alejandrobailo94@gmail.com>
2026-08-27 13:54:15 +02:00
Muhammad Ibrahimandpedrooot 301edea7ce feat(compliance): add Cyber Essentials 3.3 for Azure (#11588)
Co-authored-by: pedrooot <pedromarting3@gmail.com>
2026-08-27 13:31:18 +02:00
c89d900aae fix(iac): raise typed exceptions instead of sys.exit on provider failures (#12227)
Co-authored-by: Juhef <117518034+juheff@users.noreply.github.com>
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
2026-08-27 12:15:50 +02:00
Hugo Pereira Brito 4cfb4eeb96 fix(sdk): use system trust store for push-to-cloud (#12485) 2026-08-27 11:07:14 +01:00
Pedro Martínandalejandrobailo f19478f2f6 fix(compliance): discover universal frameworks from entry point (#12536)
Co-authored-by: alejandrobailo <alejandrobailo94@gmail.com>
2026-08-27 09:17:39 +02:00
Chethas DileepandDaniel Barranquero 2f11b16299 feat(github): add repository_default_workflow_permissions_read_only check (#12143)
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
2026-08-27 09:00:42 +02:00
Pablo Fernandez Guerra (PFE) 654d2c9f17 docs: document Slack channel destinations for alerts (#12496) 2026-08-27 08:53:07 +02:00
Chethas DileepandDaniel Barranquero 2721d42594 feat(github): add organization_actions_pull_request_approval_disabled check (#12394)
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
2026-08-27 08:25:32 +02:00
Daniel Barranquero bd1956446d fix(alibabacloud): read OSS bucket sub-resource configs via the SDK execute path (#12546) 2026-08-26 16:41:13 +02:00
Pablo Fernandez Guerra (PFE) d26d7cf91a feat(ui): show a rule's destinations in the alerts list (#12493) 2026-08-26 13:36:31 +02:00
Pablo Fernandez Guerra (PFE) 4c20bf1fac feat(ui): let alert rules target authorized Slack channels (#12492) 2026-08-26 12:55:49 +02:00
Chethas DileepandDaniel Barranquero 9dc53ffc60 feat(github): add organization_default_workflow_permissions_read_only check (#12122)
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
2026-08-26 12:21:49 +02:00
Alan Buscagliaandalejandrobailo 95642fb220 feat(ui): add Lighthouse request outcome feedback (#12419)
Co-authored-by: alejandrobailo <alejandrobailo94@gmail.com>
2026-08-26 11:34:40 +02:00
Pedro Martín 6449f3a592 fix(container): patch the high OpenSSL CVEs for container img (#12549) 2026-08-26 11:10:55 +02:00